First published: Wed Jan 08 2003(Updated: )
Internet Message (IM) 141-18 and earlier uses predictable file and directory names, which allows local users to (1) obtain unauthorized directory permissions via a temporary directory used by impwagent, and (2) overwrite and create arbitrary files via immknmz.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Debian Internet Message | =141-0 | |
Debian Internet Message | =133-0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1395 is classified as a moderate severity vulnerability due to the potential for unauthorized access and file manipulation by local users.
To fix CVE-2002-1395, update to the latest version of the Internet Message software that resolves the predictable file and directory names issue.
CVE-2002-1395 affects users of Internet Message versions 141-0 and 133-0 on Debian systems.
CVE-2002-1395 can enable local attackers to gain unauthorized directory permissions and manipulate files on compromised systems.
While CVE-2002-1395 was documented in 2002, systems still running the affected versions without updates remain at risk.